Title: [288506] branches/safari-613-branch
Revision
288506
Author
[email protected]
Date
2022-01-24 17:55:20 -0800 (Mon, 24 Jan 2022)

Log Message

Cherry-pick r288039. rdar://problem/79220540

    [iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
    https://bugs.webkit.org/show_bug.cgi?id=235248
    rdar://79220540

    Reviewed by Tim Horton and Aditya Keerthi.

    Source/WebKit:

    It's possible for `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:` to return a `nil` snapshot
    view in the case where a screen update has not been performed yet (among other scenarios). In the case where
    UIKit returns `nil` when we're creating the targeted preview for the context menu when focusing a select element
    or file input, we'll crash due to an Objective-C exception in the initializer of UITargetedPreview. Mitigate
    this by falling back to an empty UIView after requesting the snapshot view to make our code robust against this
    scenario.

    Test: KeyboardInputTests.DoNotCrashWhenFocusingSelectWithoutViewSnapshot

    * UIProcess/ios/WKContentViewInteraction.mm:
    (createFallbackTargetedPreview):

    Tools:

    Add an API test that exercises the crash by forcing `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:`
    to return nil via swizzling.

    * TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm:
    (TestWebKitAPI::nilResizableSnapshotViewFromRect):
    (TestWebKitAPI::TEST):

    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288039 268f45cc-cd09-0410-ab3c-d52691b4dbfc

Modified Paths

Diff

Modified: branches/safari-613-branch/Source/WebKit/ChangeLog (288505 => 288506)


--- branches/safari-613-branch/Source/WebKit/ChangeLog	2022-01-25 01:55:17 UTC (rev 288505)
+++ branches/safari-613-branch/Source/WebKit/ChangeLog	2022-01-25 01:55:20 UTC (rev 288506)
@@ -1,5 +1,61 @@
 2022-01-24  Alan Coon  <[email protected]>
 
+        Cherry-pick r288039. rdar://problem/79220540
+
+    [iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
+    https://bugs.webkit.org/show_bug.cgi?id=235248
+    rdar://79220540
+    
+    Reviewed by Tim Horton and Aditya Keerthi.
+    
+    Source/WebKit:
+    
+    It's possible for `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:` to return a `nil` snapshot
+    view in the case where a screen update has not been performed yet (among other scenarios). In the case where
+    UIKit returns `nil` when we're creating the targeted preview for the context menu when focusing a select element
+    or file input, we'll crash due to an Objective-C exception in the initializer of UITargetedPreview. Mitigate
+    this by falling back to an empty UIView after requesting the snapshot view to make our code robust against this
+    scenario.
+    
+    Test: KeyboardInputTests.DoNotCrashWhenFocusingSelectWithoutViewSnapshot
+    
+    * UIProcess/ios/WKContentViewInteraction.mm:
+    (createFallbackTargetedPreview):
+    
+    Tools:
+    
+    Add an API test that exercises the crash by forcing `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:`
+    to return nil via swizzling.
+    
+    * TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm:
+    (TestWebKitAPI::nilResizableSnapshotViewFromRect):
+    (TestWebKitAPI::TEST):
+    
+    
+    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288039 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+    2022-01-14  Wenson Hsieh  <[email protected]>
+
+            [iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
+            https://bugs.webkit.org/show_bug.cgi?id=235248
+            rdar://79220540
+
+            Reviewed by Tim Horton and Aditya Keerthi.
+
+            It's possible for `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:` to return a `nil` snapshot
+            view in the case where a screen update has not been performed yet (among other scenarios). In the case where
+            UIKit returns `nil` when we're creating the targeted preview for the context menu when focusing a select element
+            or file input, we'll crash due to an Objective-C exception in the initializer of UITargetedPreview. Mitigate
+            this by falling back to an empty UIView after requesting the snapshot view to make our code robust against this
+            scenario.
+
+            Test: KeyboardInputTests.DoNotCrashWhenFocusingSelectWithoutViewSnapshot
+
+            * UIProcess/ios/WKContentViewInteraction.mm:
+            (createFallbackTargetedPreview):
+
+2022-01-24  Alan Coon  <[email protected]>
+
         Cherry-pick r288034. rdar://problem/86341944
 
     REGRESSION:  ARKit example loads a page full of random symbols instead of a 3D model

Modified: branches/safari-613-branch/Source/WebKit/UIProcess/ios/WKContentViewInteraction.mm (288505 => 288506)


--- branches/safari-613-branch/Source/WebKit/UIProcess/ios/WKContentViewInteraction.mm	2022-01-25 01:55:17 UTC (rev 288505)
+++ branches/safari-613-branch/Source/WebKit/UIProcess/ios/WKContentViewInteraction.mm	2022-01-25 01:55:20 UTC (rev 288506)
@@ -8646,7 +8646,9 @@
     if (backgroundColor)
         [parameters setBackgroundColor:backgroundColor];
 
-    UIView *snapshotView = [rootView resizableSnapshotViewFromRect:frameInRootViewCoordinates afterScreenUpdates:NO withCapInsets:UIEdgeInsetsZero];
+    RetainPtr snapshotView = [rootView resizableSnapshotViewFromRect:frameInRootViewCoordinates afterScreenUpdates:NO withCapInsets:UIEdgeInsetsZero];
+    if (!snapshotView)
+        snapshotView = adoptNS([UIView new]);
 
     CGRect frameInContainerViewCoordinates = [rootView convertRect:frameInRootViewCoordinates toView:containerView];
 
@@ -8653,12 +8655,12 @@
     if (CGRectIsEmpty(frameInContainerViewCoordinates))
         return nil;
 
-    snapshotView.frame = frameInContainerViewCoordinates;
+    [snapshotView setFrame:frameInContainerViewCoordinates];
 
     CGPoint centerInContainerViewCoordinates = CGPointMake(CGRectGetMidX(frameInContainerViewCoordinates), CGRectGetMidY(frameInContainerViewCoordinates));
     auto target = adoptNS([[UIPreviewTarget alloc] initWithContainer:containerView center:centerInContainerViewCoordinates]);
 
-    return adoptNS([[UITargetedPreview alloc] initWithView:snapshotView parameters:parameters.get() target:target.get()]);
+    return adoptNS([[UITargetedPreview alloc] initWithView:snapshotView.get() parameters:parameters.get() target:target.get()]);
 }
 
 - (UITargetedPreview *)_createTargetedContextMenuHintPreviewForFocusedElement

Modified: branches/safari-613-branch/Tools/ChangeLog (288505 => 288506)


--- branches/safari-613-branch/Tools/ChangeLog	2022-01-25 01:55:17 UTC (rev 288505)
+++ branches/safari-613-branch/Tools/ChangeLog	2022-01-25 01:55:20 UTC (rev 288506)
@@ -1,5 +1,56 @@
 2022-01-24  Alan Coon  <[email protected]>
 
+        Cherry-pick r288039. rdar://problem/79220540
+
+    [iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
+    https://bugs.webkit.org/show_bug.cgi?id=235248
+    rdar://79220540
+    
+    Reviewed by Tim Horton and Aditya Keerthi.
+    
+    Source/WebKit:
+    
+    It's possible for `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:` to return a `nil` snapshot
+    view in the case where a screen update has not been performed yet (among other scenarios). In the case where
+    UIKit returns `nil` when we're creating the targeted preview for the context menu when focusing a select element
+    or file input, we'll crash due to an Objective-C exception in the initializer of UITargetedPreview. Mitigate
+    this by falling back to an empty UIView after requesting the snapshot view to make our code robust against this
+    scenario.
+    
+    Test: KeyboardInputTests.DoNotCrashWhenFocusingSelectWithoutViewSnapshot
+    
+    * UIProcess/ios/WKContentViewInteraction.mm:
+    (createFallbackTargetedPreview):
+    
+    Tools:
+    
+    Add an API test that exercises the crash by forcing `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:`
+    to return nil via swizzling.
+    
+    * TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm:
+    (TestWebKitAPI::nilResizableSnapshotViewFromRect):
+    (TestWebKitAPI::TEST):
+    
+    
+    git-svn-id: https://svn.webkit.org/repository/webkit/trunk@288039 268f45cc-cd09-0410-ab3c-d52691b4dbfc
+
+    2022-01-14  Wenson Hsieh  <[email protected]>
+
+            [iOS] Occasional crash under -[UITargetedPreview initWithView:parameters:target:] when focusing form controls
+            https://bugs.webkit.org/show_bug.cgi?id=235248
+            rdar://79220540
+
+            Reviewed by Tim Horton and Aditya Keerthi.
+
+            Add an API test that exercises the crash by forcing `-resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:`
+            to return nil via swizzling.
+
+            * TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm:
+            (TestWebKitAPI::nilResizableSnapshotViewFromRect):
+            (TestWebKitAPI::TEST):
+
+2022-01-24  Alan Coon  <[email protected]>
+
         Cherry-pick r288010. rdar://problem/87557846
 
     Expose way to encode CTAP commands with only the hash of ClientDataJSON

Modified: branches/safari-613-branch/Tools/TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm (288505 => 288506)


--- branches/safari-613-branch/Tools/TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm	2022-01-25 01:55:17 UTC (rev 288505)
+++ branches/safari-613-branch/Tools/TestWebKitAPI/Tests/ios/KeyboardInputTestsIOS.mm	2022-01-25 01:55:20 UTC (rev 288506)
@@ -826,6 +826,27 @@
     EXPECT_EQ(contentView.undoManager, undoManager);
 }
 
+static UIView * nilResizableSnapshotViewFromRect(id, SEL, CGRect, BOOL, UIEdgeInsets)
+{
+    return nil;
+}
+
+TEST(KeyboardInputTests, DoNotCrashWhenFocusingSelectWithoutViewSnapshot)
+{
+    auto webView = adoptNS([[TestWKWebView alloc] initWithFrame:CGRectMake(0, 0, 320, 500)]);
+    auto delegate = adoptNS([TestInputDelegate new]);
+    [webView _setInputDelegate:delegate.get()];
+    [delegate setFocusStartsInputSessionPolicyHandler:[](WKWebView *, id <_WKFocusedElementInfo>) {
+        return _WKFocusStartsInputSessionPolicyAllow;
+    }];
+
+    [webView synchronouslyLoadHTMLString:@"<select id='select'><option>foo</option><option>bar</option></select>"];
+
+    InstanceMethodSwizzler swizzler { UIView.class, @selector(resizableSnapshotViewFromRect:afterScreenUpdates:withCapInsets:), reinterpret_cast<IMP>(nilResizableSnapshotViewFromRect) };
+    [webView stringByEvaluatingJavaScript:@"select.focus()"];
+    [webView waitForNextPresentationUpdate];
+}
+
 } // namespace TestWebKitAPI
 
 #endif // PLATFORM(IOS_FAMILY)
_______________________________________________
webkit-changes mailing list
[email protected]
https://lists.webkit.org/mailman/listinfo/webkit-changes

Reply via email to